1. Hi, Guest,

    Currently we have three official hacks running. CSGO, Battlefield Hardline and Audition America. Be sure to check them out!

    CSGO - "50 Shades of Gaben" - CSGO Cheat

    Battlefield Hardline Cheat - FREE

    Audition Redbana Hack [ARH Modz]

    More to Come!
    Dismiss Notice
Dismiss Notice
CSGO VIP Cheats now available!! Click here to get a copy!
Dismiss Notice
Want to Shorten Your Long URL? Check out our sister website Tiniurl to solve your needs!

[Tutorial] Finding the pointer address of coordinates.

Discussion in 'Scions of Fate' started by pursuited, Apr 21, 2007.

  1. pursuited

    pursuited Retired Staff Member GzP Underground

    Messages:
    1,992
    Likes Received:
    23
    Joined:
    Nov 2, 2006
    Nope! I got a better idea!!! I just made a video tutorial for how to install the client bypass. Why not check it out! It is also in the tutorial section now. But anyways, heres the link:

    http://www.gamerzplanet.net/forums/showthread-t_161329.html

    Regards,
    Pursuited
     
  2. Celestial7

    Celestial7

    Messages:
    9
    Likes Received:
    0
    Joined:
    Apr 6, 2007
    To freeze these values :
    - right click, click "find out what writes to this adress"
    - do something in SOF that will change your health/mana
    - select the assembler instruction that showed up
    - click "show disassembler"
    - select the "MOV [your adress here], EAX". This is instruction writes the value of EAX to the address containing your health/mana value. Right click it, select "replace with code that does nothing" and do the same with the other adress.
    Or -
    Scroll up a bit until you see a "CMP EAX, EDX" followed by a "JNE adress". "CMP EAX, EDX" compares the value of your health that is displayed and the real value. If they are equal, the update code is jumped by the JNE, otherwise the update code is run. To avoid that, right click the "JNE adress", click "assemble", and change the JNE to JMP. Now, even if the values are different, the code is avoided.

    Doing this will freeze your health and mana display efficiently.

    I hope it helps you understand better how assembler works, it may be useful in other games... but I don't think it will be useful to you in SOF; as Pursuited said previously, it seems that the real values are stored server-side so you can't lock them this way.
     
  3. pursuited

    pursuited Retired Staff Member GzP Underground

    Messages:
    1,992
    Likes Received:
    23
    Joined:
    Nov 2, 2006

    There are some addresses that if you NOP them, it will have an effect ingame. This is sorta the concept used for my wallhack... just a little more indepth. This concept was also applied in making your char fly. So there are a few addresses that you can mess around with. One of which I am still trying to figure out is changing the registers for the locations. But most of them will cause the client to crash. :der:

    Regards,
    Pursuited
     
  4. joeriNL

    joeriNL

    Messages:
    2
    Likes Received:
    0
    Joined:
    May 23, 2007
    totally awesome in 2 min i can go from central valley to lvl 56 monsters to use other hacks like invisible and auto click
     
  5. pursuited

    pursuited Retired Staff Member GzP Underground

    Messages:
    1,992
    Likes Received:
    23
    Joined:
    Nov 2, 2006
    Invisible hack does not work...
     
  6. Mc.Neal

    Mc.Neal

    Messages:
    5
    Likes Received:
    0
    Joined:
    Dec 20, 2005
    hmm can someone help me if i attack the client.exe my ce get a error :/
    dont know what to do
    xtrap is disable on my sof
     
  7. luster0708

    luster0708

    Messages:
    53
    Likes Received:
    0
    Joined:
    Apr 12, 2007
    it's better if u could tell us wat is the error msg that u encounter..
    who knows how to help without knowing wat's the problem :)
     
  8. Mc.Neal

    Mc.Neal

    Messages:
    5
    Likes Received:
    0
    Joined:
    Dec 20, 2005
    some critical error from the CE
     
  9. killzone

    killzone

    Messages:
    47
    Likes Received:
    0
    Joined:
    Apr 1, 2006
    Though you can scan for your HP/MP and use it in your macro to auto heal your character. :)
    Also, if possible scan for your target so in your next bot you can set what monsters to attack what to avoid.
     
  10. wyldemdd

    wyldemdd

    Messages:
    1
    Likes Received:
    0
    Joined:
    May 5, 2007
    @ Mc. Neal

    go to your CE setting, at the extra tab un-tick all the box and you wont have the error anymore. Hope this help you.
     
  11. killzone

    killzone

    Messages:
    47
    Likes Received:
    0
    Joined:
    Apr 1, 2006
    Heres How I made my bot with Auto Heal + Coordinate recognation (for Anti-Stuck). Attack only Selected Target.
    Written in AutoIt, may also work in other programming languages.

    The game is not Scions of Fate but I hope this code will help you.
    You will wonder what the hell is "TP", TP is equal to MP or Mana Point.
    Code:
    $Process = 'YourTargetProcess.exe' ;-> Target process
    $PID = ProcessExists($Process) ;-> Get Process ID
    $Address = 0x109BE1D0 ;-> myCharacter baseaddress
    $myMaxHPoffset = 268;-> myCharacterMaxHP offset H10C
    $myCurHPoffset = 272;-> myCharacterCurHP offset H110
    $myXaddrOffset = 9178;--> my cur X location offset &H23DA
    $myYaddrOffset = 9182;--> my cur X location offset &H23DE
    $TPMaxAddrOffset = 804 ;baseaddr + &H324 (Hex 324 = Dec 804)
    $TPCurAddrOffset = 808;baseaddr + &H328 
    
    $baseAddressTargetMonster = 0x109BE280 
    $Value = "";
    dim $b
    
    $maxHP = _GetData($Address,$myMaxHPoffset)
    $curHP = _GetData($Address,$myCurHPoffset)
    $myX = _GetData($Address,$myXaddrOffset)
    $myY = _GetData($Address,$myYaddrOffset)
    $TPMaxAddr = _GetData($baseAddressTargetMonster,$TPMaxAddrOffset) 
    $TPCurAddr = _GetData($baseAddressTargetMonster,$TPCurAddrOffset) 
    
    $monsterName = _GetMonsterName($baseAddressTargetMonster)
    
    MsgBox(0,"Info", "maxHP = "&String($maxHP)& @CRLF &"curHP = "&String($curHP)& @CRLF &$monsterName&@CRLF &"My X location: "&String($myX)&@CRLF&"My Y location: "&@CRLF&$myY&@CRLF&"$TPMaxAddr : "&String($TPMaxAddr)&@CRLF&"$TPCurAddr: "&String($TPCurAddr))
    
    
    Func _GetData($Address,$myOffset)
    
       $a = _GetValue($Address)
       $a = $a + $myOffset
       $myData = _GetValue($a)
       Return $myData
    
    EndFunc
    
    Func _GetValue($Address)
    
        $OpenProcess = _MemOpen(0x38, False, $PID) 
        $byte1 = _MemRead($OpenProcess, $Address, 1) 
        $Address = $Address + 1
        $byte2 = _MemRead($OpenProcess, $Address, 1)
        $Address = $Address + 1
        $byte3 = _MemRead($OpenProcess, $Address, 1) 
        $Address = $Address + 1
        $byte4 = _MemRead($OpenProcess, $Address, 1)
        $Value = Hex($byte4, 2)&Hex($byte3, 2)&Hex($byte2, 2)&Hex($byte1, 2)
        $myInt = Dec($Value)
        _MemClose($OpenProcess) 
        Return $myInt
    EndFunc
    
    Func _GetMonsterName($baseAddressTargetMonster)
    
       $Address = _GetValue($baseAddressTargetMonster)
       $b = ""
       Do
            $a = _GetAscii($Address);
            $Address1 = $Address + 1
            $a1 = _GetAscii($Address1);
            ;MsgBox(0,"Info", "a is "&Hex($a,2)&" b is "&Hex($b,2))
            If Not (Hex($a,2) = "00" And Hex($a1,2) = "00") then 
               $b = $b & Chr($a)
            EndIf
            $Address = $Address + 1  
    
       Until (Hex($a,2) = "00" And Hex($a1,2) = "00")
    
       Return $b
    
    EndFunc
    
    Func _GetAscii($Address)
    
        $OpenProcess = _MemOpen(0x38, False, $PID) 
    
        $byte1 = _MemRead($OpenProcess, $Address, 1) 
        _MemClose($OpenProcess) 
        Return $byte1
    
    EndFunc
    
    Func _MemRead($i_hProcess, $i_lpBaseAddress, $i_nSize, $v_lpNumberOfBytesRead = '')
        Local $v_Struct = DllStructCreate ('byte[' & $i_nSize & ']')
        DllCall('kernel32.dll', 'int', 'ReadProcessMemory', 'int', $i_hProcess, 'int', $i_lpBaseAddress, 'int', DllStructGetPtr ($v_Struct, 1), 'int', $i_nSize, 'int', $v_lpNumberOfBytesRead)
        Local $v_Return = DllStructGetData ($v_Struct, 1)
        $v_Struct=0
        Return $v_Return
    EndFunc
     
  12. guto

    guto

    Messages:
    38
    Likes Received:
    0
    Joined:
    Jul 16, 2007
    I found my pointers...

    how can i found my hp and sp to freeze them?is that possible?
     
  13. bas3rd

    bas3rd

    Messages:
    1
    Likes Received:
    0
    Joined:
    Jul 2, 2007
    Thanks for the nice guide =)
     
  14. manimal555

    manimal555

    Messages:
    82
    Likes Received:
    0
    Joined:
    Jun 11, 2007
    @GUTO
    you can find the addresses by losing hp and searching for the value.
    although if u freeze them the only thing it will do is stop your client from tellin you your actual hp/chi value.
    so if you loose enough hp in game you will die even if your client shows you at full hp.
     
  15. Bl00dshade

    Bl00dshade

    Messages:
    276
    Likes Received:
    1
    Joined:
    Mar 1, 2007
    aaa crap for me there is a error. Before i could run SOF with WPE pro and stuff and it only gave me the extrap error but this time it gave me this error saying CTrap Checking - MalMdl !! in a window error box. I put in the bypass ( the niewst one)
    before it worked but now it doesn't.
     
    Last edited: Jul 25, 2007
  16. kenv202

    kenv202

    Messages:
    81
    Likes Received:
    0
    Joined:
    Jul 21, 2006
    lol...dude run the game first then launch the WPE / CE / wahever hacking program
     
  17. amk0988

    amk0988

    Messages:
    1
    Likes Received:
    0
    Joined:
    Aug 23, 2007
    i want to try.
    where to download the program.
     
  18. Darthoz

    Darthoz

    Messages:
    23
    Likes Received:
    0
    Joined:
    Jul 1, 2007
    anybody got pointers for windrift? the one posted doesnt work anymore... or at least give me some info on how to get it like is it a float or a 4byte value... and how about the archer range...

    any help would be appreciated..

    edit>

    @ persuited: i got it but how do i find the pointer. coz you said that the address changes everytime.. could you point me to the right direction...
     
    Last edited: Aug 25, 2007
  19. pursuited

    pursuited Retired Staff Member GzP Underground

    Messages:
    1,992
    Likes Received:
    23
    Joined:
    Nov 2, 2006
    Does anyone still use this?
     
  20. omarness

    omarness

    Messages:
    1
    Likes Received:
    0
    Joined:
    Nov 7, 2007
    ei pursuited where can i Download the cheat engine??? i've download some but it carries a trojan key logger...is it really safe to use??? can u give me the link for that...tnx a lot
     

Share This Page